Hard-coded AWS IAM Credentials Vulnerability in Koollab LMS
CVE-2026-63239
5.4MEDIUM
What is CVE-2026-63239?
A vulnerability in Koollab LMS involves hard-coded AWS IAM credentials that allow unauthorized access to shared multi-tenant S3 buckets and SQS queues. This flaw exposes sensitive data and gives attackers the ability to inject malicious content, manipulate job processes, or intercept emails, potentially jeopardizing the security of user data and operations.
Affected Version(s)
Koollab LMS 5.3.2
